Alerting

Unable to save objects in splunk due to "server abort"

yoshilog
Explorer

We have an issue wherein every time we attempt to create a search macro, create a lookup definition, create a new lookup, update a lookup file name, clone the mentioned knowledge objects,  Splunk responds with " Your entry was not saved. The following error was reported: server abort. splunk " Can you let us know the cause of the issue in our Splunk instance? We are currently unable to create any new search macros in this environment.

 

Capture 1.PNG

They advised that there is a workaround of updating the .conf files in the backend, however our clients don't have access to the backend, and everytime they want to update something, the request goes directly to us. Does anyone know how to resolve this issue? We need the UI to function properly as it is causing delay in delivery.

Labels (1)
0 Karma
1 Solution

yoshilog
Explorer

This issue has now been resolved. It was caused by a Tech Arch Issue wherein the server files for our server were not updated. Clients were not able to update the lookup files due to the presence of a Content Security Policy specific to our server. The unique Content Security Policy (CSP) was only applicable in our region, and the source is currently unknown.
In case you are still experiencing this issue, please reach out to your technology architect (L3 team) who handles your server and have it checked. Thank you.

View solution in original post

0 Karma

yoshilog
Explorer

This issue has now been resolved. It was caused by a Tech Arch Issue wherein the server files for our server were not updated. Clients were not able to update the lookup files due to the presence of a Content Security Policy specific to our server. The unique Content Security Policy (CSP) was only applicable in our region, and the source is currently unknown.
In case you are still experiencing this issue, please reach out to your technology architect (L3 team) who handles your server and have it checked. Thank you.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...